Detecting SoftICE ?
Bruce Klein <[email protected]> 10 May 2005 16:12:24 -0000
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
Hello all,
=20
I am writing a Win32 DLL and am currently trying to detect if SoftICE is =
present.
=20
I am trying the "classic" detection methods and for my version of SoftICE=
(4.3.2) under Windows XP, so far no method has succeeded at detecting it=
.
=20
The methods I am trying are well described in Viega & Messier's "Secure P=
rogramming Cookbook" and all over the net. One is the "Meltice" techniqu=
e that looks for a virtual device named "\.\\NTICE"; the other uses the "=
Boundschecker" method that uses int 3, with "BCHK"=20
in a register.
=20
I am having no luck with either method. Perhaps because the methods are o=
bsolete with the current version of SoftICE. Perhaps because I'm doing so=
mething stupid.
=20
Given the above, I have two questions I'm hoping someone can answer:
- Does anyone know a method to detect today's SoftICE?
- Do the other methods even work (and for what versions)?
=20
I'd be happy to post the small source or answer any further questions.
=20
Thanks in advance.